Privacy Policy
Last updated: April 10, 2026 | Version 1.0
1. What Data We Collect
Iris.Art collects biometric data including iris images, voice recordings, pulse signals, facial photographs, and handwriting samples. This data is classified as "special category" personal data under GDPR Article 9 and "sensitive personal information" under CCPA/CPRA.
2. How We Use Your Data
We process your biometric data solely to extract interpretable features and generate personalized music compositions. We do not use your data for identification, surveillance, health diagnostics, or any purpose other than art generation.
3. Data Storage & Encryption
Raw biometric data is encrypted at rest using AES-256-GCM with per-record initialization vectors. Encrypted data is stored in Supabase Storage. Feature vectors and embeddings are stored in our database with row-level security policies that restrict access to the data owner.
4. Third Parties
The following third parties process your data:
- Supabase — database and encrypted file storage
- Railway — application hosting and ML compute
- musicapi.ai — audio rendering from musical parameters (no raw biometric data is shared, only derived musical parameters)
- Stripe — payment processing (no biometric data is shared with Stripe)
5. Your Rights
You have the right to:
- Access — request a copy of all your stored data
- Delete — request complete erasure of all your data (processed within 24 hours)
- Withdraw consent — revoke your consent at any time
- Port — export your data in a machine-readable format
- Object — object to processing of your data
6. Data Retention
Your data is retained until you request deletion or until 3 years after your last activity, whichever comes first. Compositions and report cards are retained independently of raw biometric data.
7. Do Not Sell or Share
We do not sell, share, or disclose your personal information to third parties for purposes other than those described in this policy. Under CCPA/CPRA, you have the right to opt out of the sale or sharing of your personal information. Since we do not sell or share data, this right is automatically satisfied.
8. Geographic Restrictions
Iris.Art is not available to residents of Illinois, United States, due to the Illinois Biometric Information Privacy Act (BIPA).
9. Contact
For privacy inquiries, data deletion requests, or to exercise your rights, contact us at: privacy@iris.art